CVE-2026-75823
WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
| Vendor | unknown |
| Product | user frontend |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user frontend
Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Frontend
3.5.29 < 4.3.12
References
Credits
Murad Akhmedov WPScan